Okay, but it's still referenced in the ipsec configuration. In configuration mode, you can do a 'show | match <gateway_name> | display set' and see all the configuration segments that have referenced your IKE gateway and either deactivate or delete them (temporarily), if you really want to stop the session from trying to establish. I'm open to hearing other ways, if one exists. Honestly, it's probably more trouble than it's worth, but that's a judgment call on your part.